You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Ajenti has an authorization bypass during custom package installation
High severity
GitHub Reviewed
Published
Apr 1, 2026
in
ajenti/ajenti
•
Updated Apr 3, 2026
Impact
An authenticated user (using the
auth_usersplugin authentication method) could install a custom package even if this user is not superuser.Patches
This is fixed in the version 2.2.15. Users should upgrade to this version as soon as possible.
References